This Privacy Policy is required under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. It describes how CredSetu Technologies Private Limited (“CredSetu”, “we”, “us”) collects, uses, shares, and protects personal data belonging to merchants (shopkeepers) and their customers who use the CredSetu application. By creating an account or otherwise using CredSetu, you confirm that you have read and accepted this Policy. If you do not accept it, you must not use the application.
1. Who We Are and How to Reach Us
- Operated by: CredSetu Technologies Private Limited
- CIN: U62090ME2026PTC475450
- Application: CredSetu — a merchant credit management and Trust Score platform for higher-ticket informal merchants (hardware, building material, and medical/pharmacy shops)
- Grievance Officer: Harsh Khot, Founder & Director — grievance@credsetu.in
- General contact: support@credsetu.in
- Privacy queries: privacy@credsetu.in
- Registered address: C/o Renuka Khot, 143/8, Hirdao Road, Lonar, Lonar, Buldhana – 443302, Maharashtra, India
The Grievance Officer handles all privacy-related complaints and rights requests. Grievances are acknowledged within 48 hours and resolved within one month of receipt.
2. What Data We Collect
2.1 From merchants
- Name, shop name, phone number, and shop address
- Business category (hardware, building material, medical/pharmacy)
- Transaction records entered into the ledger: customer name, phone number, amount extended, amount repaid, and dates
- Device and app usage data necessary for the app to function (crash logs, app version)
2.2 From customers (entered by merchants, with consent)
- Name and phone number
- Credit transaction history as recorded by participating merchants
- Trust Score — a behavioural indicator derived from repayment patterns across participating merchants
3. Sensitive Personal Data — SPDI Declaration
The IT Act SPDI Rules 2011 define “Sensitive Personal Data or Information” to explicitly include financial information: transaction data, repayment histories, and payment behaviour. CredSetu’s core ledger and Trust Score data fall within this definition. We treat all credit transaction records, repayment histories, and Trust Score data as SPDI, and apply the collection, consent, storage, and security obligations of the 2011 Rules to this data without exception.
4. Why We Collect Your Data — Purpose Limitation
- Merchant contact details — account creation, SMS OTP login, support communication
- Customer name and phone — recording the credit ledger entry the merchant makes on your behalf
- Transaction and repayment history — generating your Trust Score
- Trust Score — displayed to other participating merchants when you seek credit at their shop, with consent obtained at onboarding
Data collected for one purpose is not repurposed for a materially different purpose without fresh, specific consent. See Section 12, Planned Features, for data uses that are not yet active.
5. Consent
We obtain consent before collecting any SPDI. Consent is collected through a tiered structure, and each tier can be reviewed and withdrawn independently from within the app:
- Account creation and ledger use — required to use CredSetu at all
- Trust Score generation — consent to generate a Trust Score from your recorded transactions
- Trust Score visibility — consent for other participating merchants to see your Trust Score when you transact with them
Additional consent tiers for features described in Section 12 will be added, and separately requested, as those features launch.
6. Who We Share Data With
- SMS/DLT delivery partner (MSG91) — your phone number and OTP, solely to deliver login and consent one-time passcodes
- AWS (Amazon Web Services), Mumbai region — all application data, as our cloud infrastructure and hosting provider. Data is stored in India.
- Other participating merchants — a customer’s Trust Score is visible to a merchant only when that same customer engages with that merchant’s shop, and only with consent obtained at customer onboarding
- Analytics providers — none at this time. If an analytics tool is introduced, this Policy will be updated and users notified at least 30 days before the change takes effect.
We do not sell personal data to any third party.
We do not share Trust Score data, ledger data, or any customer financial information with any bank, NBFC, or RBI-regulated financial institution for the purpose of making a lending or credit decision. This boundary will only change if we obtain a licensed Credit Information Company structure and separately notify and re-consent affected users.
7. Data Retention
- Credit transaction / ledger records — 7 years from the date of the last transaction
- Account and profile data — duration of active account, plus 1 year after closure
- Consent records — 7 years from the date consent was recorded
8. Your Rights
- Right to access — request a copy of the personal data we hold about you
- Right to correction — where you dispute the accuracy of recorded data, the disputed record is flagged, you and the relevant merchant are both notified, and the Trust Score is recalculated once the correction is confirmed
- Right to erasure — request deletion of your data, subject to the statutory retention requirements in Section 7. Personal identifiers are deleted and transaction history is anonymised to aggregate statistics; the Trust Score tied to your identity is deleted.
- Right to withdraw consent — withdraw any consent given, at any time, from within the app or by writing to us
- Right to grievance redressal — raise a complaint with our Grievance Officer, acknowledged within 48 hours and resolved within one month
To exercise any of these rights, write to privacy@credsetu.in. An in-app self-service section for these requests is planned; until it ships, all requests are handled by the Grievance Officer at the email above.
9. Data Storage and Security
All data is stored on AWS infrastructure in the Mumbai (ap-south-1) region.
- Encryption in transit: TLS 1.2 or higher on all data transmission
- Encryption at rest: AES-256
- Access to production data is restricted to authorised personnel on a least-privilege basis
- Multi-factor authentication is enforced on all administrative accounts
10. Trust Score and the CIC Act, 2005
Trust Scores generated by CredSetu are not credit scores or credit information as defined under the Credit Information Companies (Regulation) Act, 2005. They are a behavioural indicator derived from merchant-reported repayment data, shared only among participating merchants for their own independent credit decisions. CredSetu does not currently hold, and does not require, a Credit Information Company licence for this activity. This position is a reasoned legal interpretation; it has not been tested by an Indian court or adjudicated by the RBI.
11. Children and Minors
CredSetu is not directed at, and is not available to, individuals under 18. Date of birth is verified at registration, and registration is rejected for any applicant under 18. We do not knowingly collect or process the personal data of minors.
12. Planned Features
The following are planned but not yet active in the CredSetu app. No data is currently collected, generated, or shared for these purposes:
- Automated payment reminders and associated recovery fees
- Peer “vouchers” between customers
- Cross-merchant contagion alerts
- Automatic notification when a merchant checks your Trust Score
This Policy will be updated with full details of each feature, and your explicit, separate consent will be requested, before any of them go live for your account.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via in-app notification and, where you have provided one, an SMS or WhatsApp message, at least 30 days before taking effect. Continued use of CredSetu after a change takes effect constitutes acceptance of the updated Policy.
14. Governing Law
This Policy is governed by the laws of India. Courts at Buldhana, Maharashtra, and the Nagpur Bench of the Bombay High Court, shall have exclusive jurisdiction over any dispute arising from this Policy, without prejudice to any statutory forum available under the IT Act or the DPDP Act.
15. Contact
For any questions about this Privacy Policy: privacy@credsetu.in